Ryan Kozak
27 exploits
Active since Oct 2024
All-in-One WP Migration & Backup <7.86 - Code Injection
eMagicOne Store Manager <1.2.5 - RCE
eMagicOne Store Manager for WooCommerce <1.2.5 - Info Disclosure
CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload via actualizador_git.php
WPCenter AiBud WP <1.8.5 - Code Injection
Alex Reservations: Smart Restaurant Booking <2.2.3 - File Upload
CVSS 7.2
WordPress Download Plugin <2.2.8 - RCE
CVSS 7.2
StoreEngine < 1.5.0 - Authenticated Arbitrary File Upload via CSV Import Function
CVSS 8.8
StoreEngine <1.5.0 - Path Traversal
CVSS 6.5
Themefic Instantio <= 3.3.16 - Unauthenticated Arbitrary File Upload
CVSS 6.6
eMagicOne Store Manager - Path Traversal
CVSS 9.1
Themefic Ultimate Before After Image ... - Unrestricted File Upload
CVSS 9.1
WPvivid Backup & Migration < 0.9.116 - Authenticated Arbitrary File Upload via wpvivid_upload_import_files
CVSS 7.2
Ultra Addons for Contact Form 7 <3.5.12 - File Upload
CVSS 7.2
S2B AI Assistant for WordPress - Arbitrary File Upload
CVSS 7.2
AI Engine for WordPress: ChatGPT - Arbitrary File Read
CVSS 6.5
Kalrav AI Agent <2.3.3 - File Upload
CVSS 9.8
AI Feeds <= 1.0.11 - Unauthenticated Arbitrary File Upload via actualizador_git.php
CVSS 9.8
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_file() Function
CVSS 8.1
WP Directory Kit <= 1.4.4 - Unauthenticated Authentication Bypass via Weak Auto-Login Token
CVSS 10.0
WPvivid Backup & Migration < 0.9.112 - Authenticated Arbitrary File Upload via upload_files Function
CVSS 7.2
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
CVSS 7.2
eMagicOne Store Manager for WooCommerce <1.2.5 - Info Disclosure
CVSS 5.9
eMagicOne Store Manager - Path Traversal
CVSS 9.1
Themefic Instantio <= 3.3.16 - Unauthenticated Arbitrary File Upload
CVSS 6.6